PRIVATE TEST EDITION · DRAFT FOR REVIEW
Privacy Policy
Version 2026-10-08-draft-2 · October 8, 2026
Information in this test edition
The hosting platform supplies a signed-in account identifier, email address and sometimes a display name. Firebox Junction stores the identifier, the name you choose, your profile details, photos, favorite railroads, Logbook visits, posts, comments, agreement versions and acceptance times, notification preferences, reports and moderator requests. Email is used by the server to recognize the owner’s moderator account; the app does not publish your sign-in email on your profile. Hosting providers may process request and security logs.
Why we use it
We use this information to provide member profiles, the shared feed, railroad views, Logbook records, photo storage, moderation, account controls and agreement records. We collect an age attestation rather than your full date of birth. Optional hometown information helps describe your profile; future local event alerts would use your saved preferences.
What other members can see
Members can see your display name, profile picture, bio, favorite railroads, posts, comments and Logbook entries. Hometown and state are hidden by default and are shown only when you select the visibility checkbox. Hidden location details are not included in member-facing profile responses. Your sign-in email, private notification choices, acceptance records, report identity and moderator requests are not shown in the feed. The owner can review reports and requests. Avoid including private information in public captions or photographs.
Photos
Uploaded photographs are stored separately from profile and post records and served through authenticated routes. The normal upload screen resizes and re-encodes photographs before sending them; do not rely on that alone to remove every identifying detail. Check the image itself for addresses, tickets and other private information before sharing. We do not use continuous device location tracking. If you choose Use my location on the railroad map, the browser requests location permission and uses a one-time position to calculate approximate distances. That position stays in the current map session and is not saved in your profile or sent to the community API. Map tile requests may reveal the area you are viewing to OpenStreetMap. You can instead pan to a destination and search that area.
Service providers and external websites
This private edition uses OpenAI Sites for hosting and sign-in, and Cloudflare infrastructure for structured records and photo storage. Supabase and Resend have been configured for a planned independent email-account flow, which is not active in this edition. If that flow is activated, the policy will be updated to explain the resulting processing. Railroad and ticket links take you to independent websites with their own privacy practices. The map view loads OpenStreetMap content, which may receive network information such as your IP address.
Messages and preferences
Nearby-event alerts and marketing emails are not being sent in this edition. You can separately save an optional preference for either future feature and change it in Account. Neither preference is required for membership, and neither is bundled with acceptance of the Terms. Account and security notices needed to run a future email-account service would be separate from marketing.
Retention and deletion
Community information is kept while your profile exists. Removing a post or comment hides it from members but may retain it for moderation until account deletion. You can delete your community profile in Account, which removes its stored photos and associated profile, posts, comments, Logbook entries, reports submitted by you, requests and agreement records. This does not delete your separate ChatGPT account. Hosting security logs, backups and records required for legal obligations may persist under provider retention schedules; deletion from the live community does not guarantee immediate removal from every backup. Reports submitted by others may retain their description of a concern.
Your choices and questions
Edit your profile, hide your hometown, change notification preferences and remove your own posts or Logbook entries in the app. Use Account → Contact moderator to request help, information about your data, correction, export or to raise a privacy concern. These requests are delivered to the owner’s moderator queue. You may also delete your community profile directly.
Cookies, security and updates
The hosting sign-in process uses authentication mechanisms such as cookies. This app does not add advertising trackers or sell member information in this edition. We use authentication and server-side ownership checks to restrict changes to member records; no system can promise absolute security. Material changes to these practices will be reflected here and shown in the agreement flow.
These documents describe the current private test edition and have not yet received legal review.
Back to your account